URLhaus Database

You are currently viewing the URLhaus database entry for http://hesa.co.id/_errorpages/swift/0524472928859781/XuuWnZ/ which is being or has been used to serve malware. Please consider that URLhaus does not differentiate between websites that have been compromised by hackers and such that has been setup by cybercriminals for the sole purpose of serving malware.

Database Entry




ID:732045
URL: http://hesa.co.id/_errorpages/swift/0524472928859781/XuuWnZ/
URL Status:Offline
Host: hesa.co.id
Date added:2020-10-22 01:42:07 UTC
Last online:2021-03-16 15:XX:XX UTC
Threat:Malware download Malware download
URLhaus blocklist:Not blocked
Spamhaus DBL :Not blocked
SURBL :Not blocked
Quad9 :Not blocked
AdGuard :Not blocked
Cloudflare :Not blocked
dns0.eu :Not blocked
ProtonDNS :Not blocked
OpenBLD :Not blocked
DNS4EU :Blocked
Reporter: Cryptolaemus1
Abuse complaint sent (?): Yes (2020-10-22 01:44:02 UTC to abuse{at}sentradata[dot]id)
Takedown time:4 months, 25 days, 13 hours, 20 minutes Bad (down since 2021-03-16 15:05:01 UTC)
Tags:doc emotet link epoch3 heodo link

Payload delivery


The table below documents all payloads that URLhaus retrieved from this particular URL.

FirstseenFilenameFile TypePayload (SHA256)VTBazaarSignature
2020-10-22Copy invoice #990217.docdoc 59235980108e00a0011ebeca9348c5a39ef6d6ec0b052e15ddeb825e9c21e3d5Virustotal results 39.66%Heodo
2020-10-22Form - Oct 23, 2020.docdoc 2cca3269dacdac8141ad888ba2f249ad5ef57c0bcd8c1a7946106f976f21ae03Virustotal results 42.37% Heodo
2020-10-22Inv. 037619041.docdoc 3f9db285b73fd517a1c511a147a4cae314a29a33332f7e8012700c086132b6c2n/a Heodo
2020-10-22invoices 40821 & 61373.docdoc 73afab923f309960ba6ef1f00b4d373abce5e6605b10a2b214ca42b7736f1f6bVirustotal results 40.74% Heodo
2020-10-22PO# 10232020.docdoc 8b5f6da01149406c0cd0e243ce84b34813ff8c9f09fcf645859516d085f9ae3bn/a Heodo
2020-10-22invoice #698480.docdoc bb214d27a58047c8b6ebd1a5d42662f7e28ba5346b810529cf482b5d159d60ban/a Heodo
2020-10-22XFQ-100120 YPPR-102220.docdoc a92e9fd1aaea72831f29e20e4afe829f2fd63c7645e2ae3b8b4786a8ade2b0b6Virustotal results 37.70% Heodo
2020-10-22October invoice.docdoc 69ffe894394d85585f7b58a501710dd783a3cece15ba7964b4080f3c0de17353Virustotal results 39.34% Heodo
2020-10-22005297266.docdoc 8ce84cc08c61ef8da560dab9863109bab6dac208bdb030c9d513aa71dc7b3492Virustotal results 39.62% Heodo
2020-10-22Copy invoice #779748.docdoc 0dd7566d93fe470be42c3b43f89d10022539dd21c040c3af9f234f5cdf3f580eVirustotal results 36.07% Heodo
2020-10-22Inv. 413105165.docdoc d078837cdc9042641925b36475f87954994b19f05d89c10b4ab4a1ea28a806efVirustotal results 39.62% Heodo
2020-10-22October Invoice.docdoc a53f4bb796189439737207c506acde597330328109ac2d78b693d2d6a72e4ba8Virustotal results 32.79% Heodo
2020-10-22INV #07253 FOR PO #033723980408.docdoc 2f11fb391c4e5106c86f7af02261b1ce605f84877b62af40538177fc258c9e05Virustotal results 35.85% Heodo
2020-10-22Payment.docdoc 54e4fc3613affad5354fc1058f7879031c1191f2e8e79b72df4673bae4603695Virustotal results 50.00% Heodo
2020-10-22Payment status.docdoc d824b5e0284791def5164b247df302a6cd675374f606a82564092fab93e442d4Virustotal results 51.61% Heodo
2020-10-22Electronic form.docdoc 3d931f3056e01ac585facd9cd6b2295bd63dbc6e340ccc4d94549533f42558e4Virustotal results 46.30% Heodo
2020-10-22INV_230348.docdoc 8c15a10ed4c619cdc9eefbb7d32596330ccb2dbc41b5e21841dd141fee55a85bVirustotal results 47.17% Heodo
2020-10-22E61 invoicing.docdoc fe69570cfe43c056f36d0a40929d53d4532cd181924613bda7436913979c33cbn/a Heodo
2020-10-22Y-100120 BBFC-102220.docdoc 64ee7027b8c1fc6f5a53589c1b063a42cf59f5a99924588ae219a9950fbe7130Virustotal results 46.67% Heodo
2020-10-22Form.docdoc df51e418e047ba848de075954ab841887fafe6e47c6b7b6d529222e3795ecb23Virustotal results 47.54% Heodo
2020-10-22invoice #9085.docdoc a89a346ba95533594891a15e53625209199e68bad7519485b3bfaf1954b2a8b8Virustotal results 45.16% Heodo
2020-10-22Inv_029460.docdoc 7132fddab8ccd72577838968f3e91a36c9ce64950fde88e34635e5e008be8a13Virustotal results 43.33% Heodo
2020-10-22Inv_023362.docdoc c0cccadc44aaa5274573830ea82eef9cda6607a02db099ce12c138cf50bb267fVirustotal results 44.23% Heodo
2020-10-22Invoice.docdoc 889113bf50a9e3543f97ca07e4e572f2328587944be4de82f441ba1b23e6ece1Virustotal results 38.89% Heodo
2020-10-22invoices 387 & 84709.docdoc ab4a558e5f07f221ed6052698d5a9d1b3654ab56380486df8f091e1176d3af1en/a Heodo
2020-10-22Inv. 0055937.docdoc d6671f0d5ced27402e2985dc7eb1a0d85cb46f4ce6608a60930601b847030cb7Virustotal results 45.16%Heodo
2020-10-22WR-100120 MDSB-102220.docdoc 055119f6a2254b8e3290900b29c2b27583428faa9f051bcf3b7c9a31f309f052Virustotal results 45.16% Heodo
2020-10-22PO# 10222020.docdoc 90828b96547b35641ebd76b91c0200f8f057974be00f528002acf24663c9991fVirustotal results 51.85%Heodo